CWE-11: ASP.NET Misconfiguration: Creating Debug Binary
Debugging messages help attackers learn about the system and plan a form of attack.
Last updated
Overview
ASP .NET applications can be configured to produce debug binaries. These binaries give detailed debugging messages and should not be used in production environments. Debug binaries are meant to be used in a development or testing environment and can pose a security risk if they are deployed to production.
Background
The debug attribute of the tag defines whether compiled binaries should include debugging information. The use of debug binaries causes an application to provide as much information about itself as possible to the user.
Real-world CVEs
2 recorded CVEs are caused by CWE-11 (ASP.NET Misconfiguration: Creating Debug Binary). The highest-severity and most recent are shown first.
Common consequences
What can happen when CWE-11 is exploited.
Read Application Data